CVE-2026-1542

The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Configurations

No configuration.

History

02 Mar 2026, 15:16

Type Values Removed Values Added
CWE CWE-502
Summary
  • (es) El plugin de WordPress Super Stage WP hasta la versión 1.0.1 deserializa la entrada del usuario a través de REQUEST, lo que podría permitir a usuarios no autenticados realizar una inyección de objetos PHP cuando un gadget adecuado está presente en el blog.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

28 Feb 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-28 06:16

Updated : 2026-03-02 20:30


NVD link : CVE-2026-1542

Mitre link : CVE-2026-1542

CVE.ORG link : CVE-2026-1542


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data